Resources

On Demand Webinar - Unmasking Supply Chain Risks in the Financial Services Sector

A candid panel with Marsh and St. James's Place on concentration risk, hidden dependencies, and how to get the board to act on both.
Risk Ledger
|
Company
mins read
On Demand Webinar - Unmasking Supply Chain Risks in the Financial Services Sector

Most financial services firms know, roughly, that a handful of providers sit underneath almost everything they depend on. Far fewer can say what happens to them specifically when one of those providers goes down, or how their third parties use those same providers on their behalf.

With DORA in force and the UK's critical third parties regime now designating firms in scope, regulators are pushing the sector from static, once-a-year assurance towards something continuous and dynamic. But the regulation is the baseline, not the goal.

In this hour-long panel, Justin Kuruvilla, Chief Cybersecurity Strategist at Risk Ledger, is joined by Vikas Patel of Marsh and Daniel Garcia of St. James's Place for an unscripted conversation about what supply chain resilience looks like in practice: how to find hidden dependencies, how to talk about them in business terms rather than RTOs and RPOs, and why the sector's exposure is increasingly a collective problem rather than an individual one.

The discussion ranges across AI governance in the supply chain, post-quantum cryptography, data sovereignty and the industry collaboration now emerging through trade associations and regulator-convened forums.

What you'll learn

  • Why annual questionnaires no longer satisfy regulators, and what continuous, dynamic assurance actually looks like
  • How to trace concentration risk and hidden dependencies beyond your direct suppliers into fourth and fifth parties
  • How to frame supply chain risk at board level as competitive advantage and revenue opportunity, not just loss avoidance
  • What accountability regimes like SMCR and DORA mean for personal liability, and why that makes the board conversation easier
  • How to bring AI into third-party risk management: which model your supplier is using, what data reaches it, and where ISO 42001 helps
  • A practical, hype-free view of post-quantum cryptography: what to do this quarter, and what can wait
  • Why scenario-specific tabletop exercises land with boards where generic "we need resilience" arguments do not
  • What sector-wide collaboration looks like in practice, and how to plug into it

Speakers

Justin Kuruvilla — Chief Cybersecurity Strategist, Risk Ledger

Vikas Patel — Cybersecurity Solutions Manager, Marsh25 years in cybersecurity, from the SOC to consultancy to seven years as a CISO at an insurance broker, now bringing breach and posture data to Marsh's clients.

Daniel Garcia — Risk and Governance Business Partner, St. James's PlaceDecades supporting financial organisations on governance, resilience and compliance across LATAM, Europe and Asia.

"Resilience is a sum of parts. It's not just a word."— Daniel Garcia, St. James's Place

"Don't expect a regulation to do the homework for you."— Daniel Garcia, St. James's Place

"If you look at the organisation that doesn't have the impact, they have a competitive advantage."— Vikas Patel, Marsh

"A supply chain is a living, breathing entity. The way the map looks today is not the same as it's going to look in a month."— Justin Kuruvilla, Risk Ledger

Videos & Webinars

Download for free

Pattern Trapezoid Mesh

Get the security manager's briefing

Monthly research, case studies and practical guides you won't find anywhere else.

Join thousands of security managers turning their TPRM programmes into success stories.